OESA-2021-1042

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1042
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1042.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1042
Upstream
Published
2021-03-05T11:02:37Z
Modified
2025-08-12T05:05:46.807216Z
Summary
dovecot security update
Details

Security Fix(es):

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.(CVE-2020-25275)

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).(CVE-2020-24386)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS / dovecot

Package

Name
dovecot
Purl
pkg:rpm/openEuler/dovecot&distro=openEuler-20.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.10.1-4.oe1

Ecosystem specific

{
    "src": [
        "dovecot-2.3.10.1-4.oe1.src.rpm",
        "dovecot-2.3.10.1-4.oe1.src.rpm"
    ],
    "x86_64": [
        "dovecot-help-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-help-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "dovecot-help-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-help-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP1 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/openEuler/dovecot&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.10.1-4.oe1

Ecosystem specific

{
    "src": [
        "dovecot-2.3.10.1-4.oe1.src.rpm"
    ],
    "x86_64": [
        "dovecot-help-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-2.3.10.1-4.oe1.x86_64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "dovecot-help-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-devel-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debuginfo-2.3.10.1-4.oe1.aarch64.rpm",
        "dovecot-debugsource-2.3.10.1-4.oe1.aarch64.rpm"
    ]
}